Gogs

Gogs

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 76.54%
  • Veröffentlicht 10.12.2025 13:23:46
  • Zuletzt bearbeitet 20.01.2026 13:47:34

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

  • EPSS 0.3%
  • Veröffentlicht 24.06.2025 03:48:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused b...

  • EPSS 0.95%
  • Veröffentlicht 24.06.2025 03:37:42
  • Zuletzt bearbeitet 21.08.2025 20:43:18

Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command execution due to an insufficient patch for CVE-2024-39931. Unprivileged user accounts can...

Medienbericht Exploit
  • EPSS 75.2%
  • Veröffentlicht 23.12.2024 16:15:07
  • Zuletzt bearbeitet 10.04.2025 14:47:42

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

Exploit
  • EPSS 0.84%
  • Veröffentlicht 23.12.2024 16:15:07
  • Zuletzt bearbeitet 10.04.2025 14:48:03

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.

Exploit
  • EPSS 14.95%
  • Veröffentlicht 15.11.2024 17:15:20
  • Zuletzt bearbeitet 21.11.2024 09:36:48

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Exploit
  • EPSS 1.77%
  • Veröffentlicht 15.11.2024 11:15:07
  • Zuletzt bearbeitet 19.11.2024 14:47:48

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.gi...

Medienbericht Exploit
  • EPSS 0.69%
  • Veröffentlicht 04.07.2024 16:15:02
  • Zuletzt bearbeitet 10.04.2025 13:45:38

Gogs through 0.13.0 allows argument injection during the tagging of a new release.

Medienbericht Exploit
  • EPSS 17.18%
  • Veröffentlicht 04.07.2024 16:15:02
  • Zuletzt bearbeitet 10.04.2025 13:44:52

Gogs through 0.13.0 allows argument injection during the previewing of changes.

  • EPSS 50.7%
  • Veröffentlicht 04.07.2024 16:15:02
  • Zuletzt bearbeitet 10.04.2025 13:43:51

Gogs through 0.13.0 allows deletion of internal files.